Skip to content Skip to footer

How to Conduct an ML/TF Risk Assessment for Your Firm

A risk assessment is where your whole AML/CTF program starts. It is the documented exercise of working out how money laundering and terrorism financing could touch your business, and how exposed each part of it is. AUSTRAC expects you to look at 4 areas: your customers, the designated services you provide, how you deliver them, and the jurisdictions you deal with. Get this right and the rest of the program almost writes itself, because the policies just respond to what you found.

The trap is treating it as a form. A template with blank fields invites you to tick boxes and move on. That is not what this is. A risk assessment is a way of scoring: for each factor you ask how easily a criminal could exploit it in your specific business, you rate it, and you write down why. AUSTRAC is clear that the reasoning has to be documented, not just the final rating. A rating with no rationale behind it does not hold up.

Figure 1. You score 4 factors for how easily each could be exploited, reach a rating, and that rating sets the CDD you run.

The 4 risk factors to cover

These 4 are the spine of any AUSTRAC risk assessment. Miss one and you have not met the obligation to identify the risks your business may reasonably face.

Your customers

Who are they, really. An Australian resident buying their own home is one thing. A discretionary trust, a company with layered ownership, or a politically exposed person is another. Complexity and opacity raise risk because they make it harder to see who actually benefits. This is where most of the real work sits.

Your designated services

Each designated service you provide carries its own exposure. High-value transactions, and services that help a customer hold structures that disguise the source of their funds or wealth, sit higher. List every service you offer and rate each one rather than averaging across the business.

Your delivery channels

How the service reaches the customer matters. Face-to-face dealing is easier to scrutinise than fully remote onboarding. Instructions arriving through a third party or intermediary, with little direct contact, are a recognised channel risk because they can hide who you are really dealing with.

Your jurisdictions

List the countries your business touches when providing services: where customers are based, where their funds come from, where structures sit. Links to higher-risk jurisdictions push risk up. You also assess proliferation financing risk as part of the same exercise, even if your answer is that you have no exposure to it.

The 2 sectors, side by side

The 4 factors are the same for everyone. What fills them in is not. Here is how they tend to look across a real estate agency and a law practice.

Risk factor

In a real estate agency

In a law practice

Customers

Overseas buyers, trust and company purchasers, buyers with complex or opaque ownership

Clients using trusts and companies, parties you never meet in person, PEPs

Designated services

Brokering high-value purchases and sales, buyer’s agent work

Conveyancing, handling client money, helping form companies and trusts

Delivery channels

In-person inspections vs fully remote deals, offers made through intermediaries

Instructions through a third party, online onboarding, acting for an absent client

Jurisdictions

Buyers or deposit funds from higher-risk countries, cross-border money

Clients or funds connected to higher-risk jurisdictions, offshore structures

 

Turning factors into a rating

Once you have identified the risks in each category, you assess them. AUSTRAC frames this as judging the scale of vulnerability: how easily each risk could be exploited to facilitate money laundering or terrorism financing. Score the inherent risk first, meaning the risk before your controls, then consider how much your controls bring it down to a residual risk you can live with. That produces a customer risk rating, usually low, medium or high. A low-risk customer is an Australian resident seeking a low-risk service with no red flags. A high-risk customer has things like an unusually complex control structure, or is seeking a service with no clear economic or lawful purpose. The rating is not the end point. It sets the depth of customer due diligence you run, with enhanced due diligence triggered at the high end.

A worked example

Take an overseas buyer purchasing a $2.5 million apartment through a company you have not dealt with before, with the deposit wired from an offshore account. Score the factors. The customer is a foreign-controlled company, so customer risk is high. The service is a high-value property purchase, so service risk is high. The funds cross a border from a jurisdiction you need to check, so jurisdiction risk is at least medium. Nothing here is low. The overall rating lands high, which means enhanced due diligence: you establish the source of the funds and the source of the buyer’s wealth, and you work out who actually controls the company before you go further. Compare that to a local resident buying a home they will live in, paying through an Australian bank, which scores low across the board and gets standard CDD. Same 4 factors, very different answers, and the rating tells you exactly how hard to look.

The regulatory detail

What the Act requires

Under the reformed Act your risk assessment must be documented and kept up to date, and it must cover money laundering, terrorism financing and proliferation financing. It has to be tailored to the nature, size and complexity of your business. It is 1 of the 2 components of your AML/CTF program, sitting alongside your policies, with the provisions at sections 26B to 26L. If you are a small, low-complexity firm, the AUSTRAC starter kit gives you a risk assessment template, but you still have to populate it with real data about your own customers, services and exposure.

How it drives the rest of the program

The risk assessment is not a standalone document you file and forget. The ratings it produces flow straight into your policies and your CDD workflow: who needs more scrutiny, when enhanced due diligence kicks in, what you collect and verify. Tooling helps here by tying each customer’s rating to the checks and the evidence trail that follow from it. If you are building from scratch, the risk assessment is step 1 of a 90-day plan to get the whole program in place.

When to review it

Treat it as a living document. You revisit it on a set cadence and whenever something material changes: a new designated service, a new client demographic, a new delivery method, an acquisition, or fresh AUSTRAC guidance. A risk assessment that describes last year’s business is not doing its job.

Common questions

What is an ML/TF risk assessment?

It is the documented exercise of identifying and rating how money laundering, terrorism financing and proliferation financing could affect your business, across your customers, services, channels and jurisdictions. It is the foundation your AML/CTF policies are built on.

What are the main risk factors?

Customers, designated services, delivery channels and jurisdictions, plus proliferation financing risk assessed in the same exercise. AUSTRAC expects all of them to be considered and the reasoning documented.

Do I need a separate risk assessment for each service?

You assess each designated service rather than averaging across the business, but they sit within one risk assessment. A firm offering both legal and conveyancing services may need to assess each line on its own terms.

Who can do the risk assessment?

Your compliance officer usually owns it, drawing on people who know the business. It does not have to be outsourced, but it does have to be informed and clearly documented. AUSTRAC’s risk products and sector indicators are a useful starting point.

How does the rating affect customer due diligence?

Directly. A low rating means standard CDD. A high rating triggers enhanced CDD, including closer checks on the source of funds and wealth. The rating is the link between the risk assessment and what you actually do at onboarding.

Sources

AUSTRAC, Step 2: Identify and assess your risks (risk assessment) (Reform)

AUSTRAC, Assigning customer risk ratings (Reform)

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Accounting for next

 

Liability limited by a scheme approved under Professional Standards Legislation

Certified Practising Accountant

Address

Suite 201 276 Pitt Street

Sydney NSW 2000

TPB 26336583
Austrac 100904920
ABN 44 643 057 354
Contact Us

Email: admin@homepedia.com.au

Phone: +61 426 816 188

Homepedia ©  All Rights Reserved.

Discover more from Homepedia

Subscribe now to keep reading and get access to the full archive.

Continue reading